# Avoiding session timeout

**URL:** <https://discuss.elastic.co/t/avoiding-session-timeout/204658>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [October 22, 2019, 2:02pm UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658 "2019-10-22T14:02:46Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![anon42972578](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Post date:** [October 22, 2019, 2:02pm UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/1 "2019-10-22T14:02:47Z")

</div>

Hello,

we are running in some issues and we dont know why.

Kibana 7.3  
Kibana session timeout 60 minutes

When we running a dashboard from the default space and refresh this dashboard every 15 minutes, we dont run into a session timeout.  
But when we running a dashboard with the same user from another space and refresh this dashboard every 15 minutes, we run into a session timeout.

Why is this happening ?

How can we avoid a session timeout with dashboard which are not in the default space ?

Best regards

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [October 22, 2019, 4:06pm UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/2 "2019-10-22T16:06:11Z")

</div>

@anon42972578, do you have `xpack.security.sessionTimeout` set in your kibana.yml? Also, what do you have set for `xpack.security.authc.providers` or `xpack.security.authProviders`?

---

<div class="post-metadata">

**Author:** ![anon42972578](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Post date:** [October 23, 2019, 8:24am UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/3 "2019-10-23T08:24:26Z")

</div>

@Brandon_Kobel  
kibana.yml:  
xpack.security.sessionTimeout: 3600000 ( 60 minutes )

xpack.security.authProviders: [saml,basic]  
server.xsrf.whitelist: [/api/security/v1/saml]

in both cases, i used basic auth via "/login" in URL with the same user.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [October 23, 2019, 1:01pm UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/4 "2019-10-23T13:01:12Z")

</div>

@anon42972578 The space that a dashboard is in shouldn't be affecting the session timeout behavior.

Do you happen to have multiple "tabs" open for Kibana in the same browser?

---

<div class="post-metadata">

**Author:** ![anon42972578](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Post date:** [October 23, 2019, 1:06pm UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/5 "2019-10-23T13:06:49Z")

</div>

i have multiple "tabs" open on my Pi, yes. But only 1 Tab is Kibana. I change the tabs via "tabs resolver".

Could it be possible that the refresh of the dashboard is not working in the background ?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [October 23, 2019, 1:50pm UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/6 "2019-10-23T13:50:23Z")

</div>

@anon42972578, it's certainly possible. What types of visualizations are in the Dashboard which is unexpectedly timing out?

---

<div class="post-metadata">

**Author:** ![anon42972578](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Post date:** [October 23, 2019, 2:04pm UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/7 "2019-10-23T14:04:05Z")

</div>

all are type = TSVB  
tried out another dashboard with timelion, working fine

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [October 23, 2019, 6:11pm UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/8 "2019-10-23T18:11:29Z")

</div>

Hey @anon42972578, there are currently a sub-set of XHR requests that are executed by Kibana which don't extend the session timeouts because they're using a "non-standard" approach. TSVB happens to be one of these. [https://github.com/elastic/kibana/pull/39477](https://github.com/elastic/kibana/pull/39477) will fix this issue, but the earliest this fix will be available is in 7.6.

It's an incredibly ugly hack, but if you add a non-TSVB Visualization to the dashboard, that should keep the dashboard from expiring your session prematurely.

---

<div class="post-metadata">

**Author:** ![anon42972578](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@anon42972578](https://discuss.elastic.co/u/anon42972578)\
**Post date:** [October 24, 2019, 6:29am UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/9 "2019-10-24T06:29:17Z")

</div>

@Brandon_Kobel  
Thank you so much!  
Adding a non-TSVB Visualization is a good workaround for us, until 7.6 is released.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2019, 6:29am UTC](https://discuss.elastic.co/t/avoiding-session-timeout/204658/10 "2019-11-21T06:29:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
